{"version":"1.0","type":"rich","provider_name":"techandbusiness.org","provider_url":"https://techandbusiness.org","title":"Malicious npm packages move execution from install hooks into runtime code","author_name":"techandbusiness.org · Cybersecurity","thumbnail_url":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjaN7aXt0PoPdZQ_VG77wkwdIyNugcdkFD6MnMvlj5LN_byw2ZrX8-gtpDld4CviuW1MOhHiElsvFtIkO9IfhBr4af-sJwM1zvR-RFICRll4G5jG4JNPX1vx4sup3omlw8uTJgro9UUfzecLMI1Whls3ihqZ9OXYJliIBjhpoodf4WI9j1lA6EUjms7x1pG/s1700-nu-rw-lo-l85-e365/rth.jpg","width":600,"height":400,"html":"<blockquote class=\"tb-newswire-embed\" style=\"max-width:600px;border-left:3px solid #22d3ee;padding:12px 16px;margin:0;font-family:-apple-system,system-ui,sans-serif;background:#09090b;border-radius:0 8px 8px 0;\">\n      <p style=\"margin:0 0 8px;font-size:10px;font-weight:600;letter-spacing:0.1em;color:#71717a;\">techandbusiness.org · Cybersecurity</p>\n      <p style=\"margin:0 0 8px;font-size:18px;font-weight:700;line-height:1.3;color:#fff;\"><a href=\"https://techandbusiness.org/newswire/HbGr9Rdca6bGslxY8c3nk8\" style=\"color:#fff;text-decoration:none;\">Malicious npm packages move execution from install hooks into runtime code</a></p>\n      <p style=\"margin:0;font-size:14px;color:#a1a1aa;line-height:1.5;\">Researchers found a malicious npm package called indexed-btree that concealed its loader inside an ordinary runtime method, bypassing defenses focused on installation scripts. The package, which mimic...</p>\n    </blockquote>"}